Glossary · OT cybersecurity
Asset owner
Also known as: Plant operator, Operator (IEC 62443)
German: Asset Owner
In IEC 62443, the asset owner is the organization that is accountable and responsible for an industrial automation and control system and operates it, typically the plant operator. It defines the security requirements, runs the security program and is responsible for the system in operation.
- OT security
- Standards
In one sentence
In IEC 62443, the asset owner is the organization that operates an industrial control system and is accountable for its cybersecurity in operation.
Example
A beverage company, as asset owner, specifies target security levels for its new bottling line and requires the system integrator to deliver according to IEC 62443-2-4.
How it applies
- Engineering: The asset owner sets the risk tolerance and the target Security level (SL) for zones, based on a Security risk assessment. The System integrator and Product supplier then design and deliver against those requirements.
- Operation: Security in operation stays with the asset owner: account management, Patch management, monitoring, Incident response and Backup and recovery are part of its security program under IEC 62443-2-1.
- Maintenance: The asset owner decides when updates are installed, balancing security against production and safety concerns.
- Documentation: Documentation teams at suppliers write for the asset owner: security manuals should state which measures the operator must take (network segmentation, account changes, update procedures) and which the product already provides. Clear Responsibility assignment avoids gaps.
Asset owner vs. product supplier vs. system integrator
IEC 62443 separates three principal roles. The product supplier develops components, the system integrator builds the automation solution from them, and the asset owner operates it. One company can hold several roles, but the responsibilities stay distinct.